๐Ÿ” CVE Alert

CVE-2026-91078

UNKNOWN 0.0

TillKit < 1.0.5 - Unauthenticated POS Takeover via Hard-Coded Default Manager PIN

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The TillKit WordPress plugin before 1.0.5 does not require the hard-coded, publicly known PIN of the privileged POS account it creates on activation to be changed before use, and it authenticates its public POS login endpoint on that PIN alone with no identity or capability check, allowing unauthenticated attackers to obtain a privileged POS session and thereby read customer and site-user personal data and modify store data.

Vendor unknown
Product tillkit
Published Oct 3, 2026
Stay Ahead of the Next One

Get instant alerts for unknown tillkit

Be the first to know when new unknown vulnerabilities affecting unknown tillkit are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / TillKit
0 < 1.0.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/7ab037d6-c670-4eaf-be0d-11cc9e20b18e/

Credits

Pedro Pinho WPScan